Skip to content

535 040 361511 275 531

Book an IT review

Change of IT company without downtime: the procedure of taking over administration

Changing IT companies rarely ends badly because of technology. It ends badly when someone terminates the contract before determining who owns the domain and where the backups really are. Here's the sequence that protects business continuity.

Jakub MazurekJuly 17, 202614 min read

Rows of closed server racks in a server room, infrastructure transferred when changing IT providers

The decision to part with the current IT supplier is usually made before anyone says it out loud. Reports hang around for several days, no one can say whether the backup was completed, and the question about documentation ends with a promise that "everything is in our system". The problem is that the decision itself does not solve anything, and a poorly managed change of IT company can cost more than another year of poor service.

The risk is rarely in the technology. It lies in the sequence of actions. The company terminates the contract, counting on a clean slate, and only then discovers that the domain is registered to the private account of the former administrator, the licences were purchased by a partner who has just ceased to be its partner, and the only copy of the database lies on a disk in the server room to which there is no password.

This resource describes the sequence that protects business continuity: first determine what you have and who controls it, then secure control, and only then end the relationship. This is an operational procedure, not legal advice, parts of the contract require a conversation with a legal advisor and we clearly state this.

When a change of supplier is justified

Not every frustration justifies a change. Some of the problems are due to the scope, which no one has ever determined, and not to the incompetence of the supplier. If the contract covers failure response and the company expects infrastructure development, the new supplier will recreate exactly the same conflict a few months later.

Change makes sense when the problem is structural and repeatable:

  • Lack of transparency. You don't know what was done, why and what you are paying for. You don't receive reports or you receive statements that show nothing.
  • Risk concentrated in one person. The entire environment is known to one person, nothing is documented, and his leave is an operational problem for the company.
  • Unverifiable backup. The provider declares backups, but cannot show proof of recovery. This is a situation in which the company learns about the backup status at the worst possible moment.
  • No response to reported risk. You report a problem, hardware without manufacturer support, no segmentation, shared administrator account, and nothing happens for a year.
  • Conflict of interest. The provider only makes money from interventions, so a stable environment is inconsistent with its revenue model.

If the reason is a one-time failure or an invoice dispute, it is worth exhausting the conversation first. Taking over administration is a project that takes several weeks and involves people on your side. It's not done out of emotion.

If you recognise at least two points from the above list, move on, the rest of the material describes how to do it without stopping your company. If you would like to discuss your own situation, please see the scope permanent IT support or write to us via contact form.

First, contract and resource ownership

This is the moment when an irreversible error is most often made. Terminating the contract before the inventory takes away your only real leverage: as long as the relationship continues, the supplier has a contractual obligation to act. After termination, all you have left is good will and the notice period, which usually runs faster than you figure out where the passwords are.

Order that works: inventory → confirmation of ownership → security of control → termination → transfer.

Before you say anything, answer these four questions.

Who is the domain registered to? No "who operates it", only who is listed as a subscriber at the registrar. A domain registered for a supplier or for the private account of his employee is a single point that can stop the e-mail and website of the entire company.

Who owns the subscription and licence? Microsoft 365 and Google Workspace are sometimes purchased by the partner. Termination of a relationship with a partner may affect the settlement of the subscription. The same applies to licences for server software and industry systems.

Where are the backups physically located and who has access to them? If the backup runs on the provider's account in their cloud, it is not your backup. This is his backup of your data, but this is a completely different legal and operational situation.

Is there a data processing agreement? If a supplier has access to systems with personal data, they process the data on your behalf. In line with the position Personal Data Protection Office (accessed 16/07/2026) processing is entrusted on the basis of a written contract, electronic form is also acceptable, and the processing entity acts only on the documented order of the administrator. The Personal Data Protection Office also points out that the responsibility for concluding such a contract rests with both parties, so the lack of a document is not only the supplier's problem.

UK Guidelines National Cyber Security Centre on selecting a managed service provider (published 24/11/2025, reviewed 24/06/2026) go in the same direction: the contract should clearly define what the supplier is responsible for and what remains with the customer, and include responsibility for third parties the supplier uses to provide the service.

Questions for legal counsel, not supplier

The following matters will be decided by your lawyer based on your specific contract. This article does not interpret them and does not replace such analysis:

  • What is the notice period and when does it start?
  • Does the contract include an obligation to cooperate in terminating cooperation and providing documentation?
  • Who owns the documentation and configuration created?
  • What are the consequences of early termination?
  • Are there any provisions for penalties, exclusivity or automatic extension?

The result of this section is to be one card: list of resources, each with the name of the formal owner and whether your company has independent access to it.

Step by Step Takeover Plan

The order below is not random. We start with the resources whose loss is the most severe and most difficult to reverse, and end with those that can be recreated.

Domains and DNS

The domain comes first because it controls the company's email and online presence, and getting it back despite the subscriber's need can be a weeks-long process.

Set up a subscriber at the registrar and gain access to the panel, preferably by transferring the domain to a company account set up at the address in your domain, and not to the employee's private mailbox. Take a full DNS zone dump and save it outside the provider's environment. It is a plain text file, but without it, restoring the email configuration is done by trial and error, on a living organism.

Do not change MX records at this stage. The goal is zone control, not service switching.

Identity and authentication

Second is the identity system, Microsoft Entra ID, Google Workspace or Active Directory. Whoever has an identity has everything connected to it.

Confirm that your company has at least one global administrator account that the supplier does not have access to, and that the account is protected by multi-factor authentication associated with the person's device. In the guidance cited, NCSC recommends that privileged accounts be protected by two-factor authentication and that the provider be granted only the privileges necessary to complete the task.

Inventory privileged accounts: who has them, since when, why and when they were last used. Also check service and application accounts, they will survive the breakup with the supplier if no one thinks about them, and they are most often left as an invisible entrance to the environment.

At this stage do not remove supplier accounts. You still need it to impart knowledge. Deletion takes place after receipt.

Devices and station management

Determine what computers are managed by: an RMM solution, Intune, domain policy, or nothing. If the managing agent belongs to the supplier, it will lose support after the separation and you need to plan its replacement at the stations, this is a simple but time-consuming operation that is better to spread over time than to make a switchover on the weekend.

List your equipment with serial numbers, personas, purchase dates, and manufacturer support status. List devices without support separately, this is a list of risks that the new supplier takes over. NCSC notes that the contract should specify who is responsible for tracking support end dates and for acting on them before they expire.

Pay attention to disk encryption. If stations are encrypted, recovery keys must be deposited in your identity system, not in the provider's tool. Losing keys when exchanging management means losing data on the device.

Network

Collect administrative access to the router, firewall, switches and access points, as well as current copies of the configuration. Write down what the segmentation looks like, what the external access rules are and who has remote access to the network via VPN.

Contracts for connections and access to operator panels are sometimes omitted and can block failure diagnostics. Check who they are for.

List each remote access separately: VPN accounts, port forwarding, remote desktop tools. This is a list that must be reviewed point by point after the cooperation ends.

Cloud and licensing

List all subscriptions: who owns them, who pays, when they expire, through which partner they were purchased. Check whether company data is living on private accounts, it's more common than you think and usually only comes out during migration.

Pay attention to industry and ERP systems. They usually have separate support contracts with the manufacturer, separate from the contract with the IT supplier, and require a separate contact person to be prescribed.

Backup

I leave the backup for the end of the sequence because it requires the most attention and is most often disappointing.

Start with a distinction that tends to get blurred in conversation:

Mechanism What it does What it doesn't do
Synchronisation (OneDrive, Google Drive) Maintains the same files on multiple devices Does not protect against deletion or encryption, change replicates to all copies
Replication Maintains a twin copy of the system, usually for availability Reproduces a bug and a harmful change; is not a step back in time
Snapshot Saves the machine state at a point in time Usually lies on the same infrastructure, shares its fate
Backup Creates a separate, reproducible copy with version history It's worth nothing without a playback test
Archiving Stores data long-term for compliance Not intended for rapid disaster recovery

Then ask the supplier three questions and ask for evidence, not declarations: what exactly is covered by the copy, where the copies are located and who has access to them, when they were last made recovery test and what was its result.

Also establish two parameters that determine what the company actually agrees to. RPO is the maximum acceptable data loss measured over time, the answer to the question "how many working hours can we lose". RTO is the maximum time to restore the service, "how long can we be down". If no one in the company knows these values, backup is not designed, just enabled.

Before proceeding, make an independent copy of your critical data that only your company has access to. This is the only element of the entire procedure that should not be postponed or delegated.

We described more about how to distinguish a working backup from a fake one in the article about data backup in the company.

Transition period and communication

A parallel period, during which the old supplier is still responsible for the environment and the new one is already learning about it, is the safest variant of change. It usually takes two to six weeks, depending on the complexity of the environment and how much has been determined during the inventory stage.

The principle of division of responsibility should be clear: the old supplier is responsible for action, the new one is responsible for knowing and preparing. Blurring this line ends in a situation where, in the event of a failure, everyone points to the other and the company stands still.

Identify one person on your side who leads the project and makes decisions. It doesn't have to be technical, but it does have to have a mandate.

Communication with the departing supplier should be factual and written. There is no need to justify decisions or enter into an argument about the past, you need specific things at a specific date. A neutral tone is not politeness, but business: the supplier in conflict gives the minimum, and you need the maximum.

Employees only need a simple message: we are changing the IT servicing company, from date Too much technical detail generates questions, not peace of mind.

Acceptance report

Handing over the environment without a protocol is a conversation that everyone will remember differently in a month. The report does not have to be a legal document, it must be a list of items with the passing criteria and a signature.

Each item should have three elements: resource, proof of execution i passing criteria. The proof is not the sentence "passwords were transferred", but the confirmed login of a person from your company or the acquiring company.

Area Proof of execution Pass criteria
Domain Screenshot of the recorder panel with subscriber data The company is listed as a subscriber and logs in independently
DNS Zone export File saved outside the old vendor's environment
Identity List of privileged accounts Company admin account is working, MFA associated with company person
Backup Recovery Test Report The specified file or system was restored and confirmed to be correct
Network Copies of device configurations New provider logs in to each device
Licences Subscription statement with owner The company owns or knows the acquisition path
Documentation Complete set provided New supplier confirms completeness after review
Supplier accounts List of accounts to be deleted Accounts disabled, then deleted after the grace period

The last item is a separate step and is performed after confirmationthat everything else works. Sequence: Disable accounts, wait for the specified grace period, check if anything has stopped working, then delete. Immediate deletion can stop a task that no one knew about and leave you unable to quickly undo the change.

Also review service accounts and integrations, connections with external systems are sometimes issued to the supplier's e-mail address.

No documentation or cooperation

Sometimes the supplier does not provide knowledge: does not respond, uses the excuse of lack of time or claims that the documentation does not exist. Usually this is not malice, but a fact - in many small IT companies, the documentation was never created and the knowledge lived in the head of one person.

Do not escalate conflict before securing control. The brawl costs you access, which you still need.

Practical order in such a situation:

  1. Apply in writing with a specific item list and deadline. The letter documents an attempt at cooperation and will be useful if the case goes to a lawyer.
  2. Restore from systems, not from stories. Domain registrar panel, operator panel, Microsoft 365 or Google Workspace consoles, network device configurations and invoices. Invoices are an underestimated source: they show what the company actually pays for, and therefore what services exist.
  3. Take back control where you own it. As a domain registrant or subscription owner, you can usually go through a process to regain access with your service provider.
  4. Assume that the knowledge is lost and plan to recreate it. New supplier inventories the environment from scratch. It costs time, but it is doable and quantifiable.
  5. Consult a lawyer, if the contract provides for an obligation to cooperate and the supplier does not fulfill it. This is the moment for a legal assessment, not for an independent interpretation of the provisions.

Borderline situation requiring immediate response: supplier refuses to cooperate and still has active access to the environment. Then securing privileged accounts becomes urgent and is done regardless of the status of conversations, while maintaining records of who changed access and when.

First 30 days of the new supplier

The takeover does not end on the date of handover. It ends when the environment is described and the company knows what to expect.

Days 1-7. The new supplier verifies the inventory and compares it with reality. At this stage, things usually come out that were not mentioned in the protocol. Starts monitoring and a reporting channel. The priority is failure detection, not optimisation.

Days 8-14. Backup verification with your own tools and the first restoration test on your side. Review of privileged accounts and deletion of those left from previous cooperation. List of critical risks, equipment without support, no segmentation, shared accounts.

Days 15-30. Supplementing the documentation to the point where the environment can be taken over by another person from the team. Setting priorities for reports and rules for handling them. First report to the management board: what was found, what was fixed, what requires decisions and money.

This report is a good measure of the quality of the first month. If after thirty days the new supplier cannot describe what he found, then the change was a move, not an acquisition.

It is also worth establishing the rules for how tickets will be handled, what the difference is between response time and repair time and who assigns priority. Agreeing on this at the start saves misunderstandings later.

Cumulative Checklist

Quick checklist of the entire procedure. The points should be completed in this order.

Before termination of the contract

  • [ ] The domain registrant has been determined and access to the registrar's panel has been obtained
  • [ ] DNS zone exported and saved outside the provider's environment
  • [ ] The company has its own administrator account with MFA in the identity system
  • [ ] Privileged, service and application accounts inventoried
  • [ ] The owner of each subscription and licence has been identified
  • [ ] Confirmed where backups are and who has access to them
  • [ ] An independent copy of critical data has been made
  • [ ] Listed hardware with serial numbers and support status
  • [ ] Network device configurations collected
  • [ ] Checked whether there is a data processing agreement
  • [ ] The lawyer assessed the terms of the notice and the obligation to cooperate

Transition period

  • [ ] The division of responsibilities between suppliers has been agreed in writing
  • [ ] A person has been appointed to lead the project on the company's side
  • [ ] The change has been communicated to employees
  • [ ] The date and scope of the transfer have been established

Pickup

  • [ ] Each protocol item has proof of completion and passing criteria
  • [ ] Backup restore test performed and result confirmed
  • [ ] The new supplier confirmed the completeness of the documentation
  • [ ] Old provider accounts disabled, graced and deleted
  • [ ] Remote access reviewed: VPN, port forwarding, remote desktop
  • [ ] Contact details for manufacturers and operators have been provided

First 30 days

  • [ ] Monitoring and reporting channel are working
  • [ ] Backup verified with the new provider's tools
  • [ ] A list of critical risks has been created
  • [ ] Documentation allows someone else to take over the environment
  • [ ] The Management Board received the opening report

Changing an IT company is a project, not a decision

The most important thing in the whole procedure is not the pace, but the order. Companies that lose data or stop working for several days almost always start by terminating the contract, and take inventory under the pressure of time and emotions. Companies that go through this calmly first determine what they have, then secure control, and talk about ending the cooperation from the position of someone who already has the keys to their own home.

If you are planning to change supplier and want to go through it without downtime, let's talk about the plan to take over the environment. We start with an inventory and a responsibility map, only on this basis can we say what is feasible and when. The scope of permanent care is described on the website IT outsourcing.


Disclaimer

The material is informative and describes operational practice. It does not constitute legal advice. Assessment of the provisions of a specific contract, the terms of its termination, the issue of ownership of resources and obligations arising from personal data protection regulations requires consultation with a legal advisor familiar with your documentation.

Sources

As of July 16, 2026

Read more in the same topic.

Free · 60 minutes online · no obligation

You want to check this out at home in your company?

  1. You talk to an engineerOnline, by video call. Not with a salesperson. We don't install or change anything.
  2. We check 8 areasBackups, access, network, email, server, licences, protection and KSeF readiness.
  3. You get a scorecardThree priorities on one page, emailed after the meeting. Yours to use however you like.

We don't use a contact form. We answer the phone and reply to emails.